Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-74994

Опубликовано: 01 сент. 2026
Источник: redhat
CVSS3: 6.5

Описание

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

A flaw was found in the mod_auth module of OTP's inets httpd server. When configured with multiple directory configuration blocks and using dets or mnesia authentication backends, the module incorrectly collapses all directory blocks into a single shared user/group namespace. This allows a user authenticated for one protected directory to gain unauthorized access to other protected directories on the same server instance, leading to an authentication bypass.

Отчет

Moderate: The mod_auth module in the inets httpd server, as shipped in Red Hat Hardened Images, is vulnerable to an authentication bypass. This flaw occurs when the server is configured with dets or mnesia authentication backends and multiple directory blocks with differing access requirements, leading to a collapse of user/group namespaces. An authenticated user for one protected directory can then access other protected directories on the same server instance, undermining intended access controls.

Меры по смягчению последствий

To mitigate this issue, avoid configuring the inets httpd server's mod_auth module with dets or mnesia authentication backends when using multiple directory blocks that require distinct user or group populations. Alternatively, ensure that all protected directories are intended to share identical user populations, thereby eliminating reliance on namespace isolation. If possible, switch to the plain authentication backend, which correctly isolates per-directory users and groups.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Not affected
Red Hat Hardened Imageserlang27-main-27.3.4.17-0.1.hum1FixedRHSA-2026:6253102.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2526857inets: otp: inets httpd mod_auth: Authentication Bypass via Directory Namespace Collapse

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
16 дней назад

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

nvd
16 дней назад

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

msrc
10 дней назад

inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth

debian
16 дней назад

The mod_auth module in OTP's inets httpd server, when configured with ...

6.5 Medium

CVSS3